Pricing
Security and trust

Every access is validated in context.

Weform combines identity, organization permissions and backend checks to separate workspaces, experiences, programs and participant data.

Current controls

The interface does not decide who can enter.

Visible controls help guide people, but effective permission is checked in rules and backend services against the current identity.

Verifiable identity

Firebase Auth identifies the user and the backend validates the ID token, including revocation, before authorizing private routes.

Organization isolation

Memberships are projected into server-managed claims and private queries are scoped to the active workspace.

Backend permissions

Sensitive member, billing, partner and administration mutations do not depend on a decision made in the browser.

Public boundary

The watch page receives a filtered projection; it does not directly read organization, media or file documents.

Courses and blocks

Program context does not grant access by itself.

Programs is in beta and reuses the same identity, publication and organization boundaries as each experience.

  • Validated contextA program key is accepted only when the program exists, is published and actually contains the experience.
  • Access applied to each experienceThe program policy is stored on its experiences so a direct link cannot bypass it.
  • Capability checkedCreating, publishing and consuming programs requires a plan with that capability; frontend and backend both verify it.
  • History without privilegesSaving a program in My programs helps resume it, but does not grant access: publication and membership are revalidated.
Data handling

Each surface exposes only what it needs.

Weform does not sell participant data. It processes data to provide the platform and may rely on necessary, documented infrastructure providers.

No data sales

Data is not used for advertising or combined across organizations.

Necessary providers

Infrastructure, payments, email and other services may act as providers or subprocessors; the platform is not presented as isolated from third parties.

Filtered public projection

Brand, cover and published resources arrive already resolved and authorized by the backend.

A file ID is not a credential

Playing media requires the context of an accessible experience or an active workspace membership.
Work in progress

Transparency before a broad promise.

This page describes verifiable controls, not a certification or absolute guarantee. These requirements must be closed and tested before the complete commercial launch.

01

Backup and restore

Documented backup and restore tests.
02

Upload validation

Complete upload validation and malicious-content strategy.
03

Incident response

Operational incident response procedure.
04

Subprocessors

Public, reviewed subprocessor inventory.
05

Retention and deletion

Legal retention, export and deletion policy.

Do you have a technical security question?

Tell us the context and we will respond with the product's real scope. This channel does not replace a legal or privacy contact.Email the team
© 2026 Weform. All rights reserved.
weformv0.51.0